Explore skills
4,475 skills found
Category alert
Get new Segurança skills every Monday
security-audit
Deep security audit covering OWASP Top 10, authentication, authorization, data protection, dependency vulnerabilities, and secrets scanning. Delegates to the Centinela (QA) agent.
aurakit
Sonnet Amplified fullstack engine. 34 modes, SEC-01~15 OWASP security, 13 runtime hooks, 75% token reduction. Install: npx @smorky85/aurakit
remediation
Get a context-aware remediation plan for a vulnerability with fix verification steps
gsd:audit-uat
Cross-phase audit of all outstanding UAT and verification items
vuln
Look up a vulnerability by ID or list all vulnerabilities for a package
exploits
Analyze exploit intelligence for a vulnerability against the current repository
fix
Get fix intelligence for a vulnerability and propose concrete remediation for the current repository
bb-local-toolkit
This skill details a complete bug bounty workflow, encompassing reconnaissance, pre-hunt learning, and vulnerability hunting for a wide range of common web exploits like IDOR, XSS, and SQLi.
bug-bounty
A complete bug bounty workflow encompassing reconnaissance (subdomain enumeration, asset discovery, fingerprinting), pre-hunt learning (disclosed reports, tech stack research), and vulnerability hunting for various issues including IDOR, SSRF, XSS, SQLi, and advanced techniques like GraphQL and HTTP smuggling.
m365-entra-attack
This skill details a Microsoft 365 / Entra ID red-team attack chain, reflecting current 2026 realities, covering AADSTS codes, user enumeration, Smart Lockout math, Conditional Access bypass, ROPC + SAML SSO flows, and Burp/Playwright templates. It's derived from authorized red-team operations that uncovered pre-existing lockouts and CA-blocked credentials, combined with real-time external attacker observations.
hunt-api-misconfig
Identifies and exploits API security misconfigurations such as mass assignment, JWT attacks, prototype pollution, CORS, and HTTP verb tampering.
hunt-race-condition
A skill for hunting race condition vulnerabilities, developed from 12 public bug bounty reports. It covers modern HTTP/2 single-packet attack cases and common scenarios like coupon double-redemption, gift-card double-spend, MFA-OTP-validate race, account-create race, and crypto token double-spend.